Skip to content

Internal audit concepts

Internal audit provides independent, objective assurance and consulting designed to add value and improve an organisation’s operations. Nextera Trace is built around the professional cycle rather than around a generic task tracker, so this page covers that cycle.

Independence is a constraint on the system, not just on the people

Section titled “Independence is a constraint on the system, not just on the people”

The defining characteristic of internal audit is that it is independent of the activities it audits. Independence is organisational — internal audit reports functionally to the audit committee and administratively to management — and objectivity is the individual equivalent: no auditor assesses work they performed or advised on.

This has direct consequences for how an audit system must behave, which is why it belongs on a concepts page rather than in a policy document:

  • Management can be given read access to results, but must not be able to alter a finding, its rating, or its evidence.
  • The person who agrees a management action and the person who verifies it was completed cannot be the same person.
  • The audit trail on ratings and conclusions matters more than in most systems, because the value of a finding is partly its unamended provenance.

The audit charter is the board-approved document establishing internal audit’s purpose, authority, reporting lines and right of access. Everything else derives from it. Internal audit’s professional framework comes from the Institute of Internal Auditors.

The audit universe is the complete population of things that could be audited — entities, business units, processes, systems, geographies, third parties, and risk themes.

Two properties make it useful rather than decorative:

  • It is maintained, not rebuilt. A universe reconstructed each year loses the history of what was audited when, which is the input the plan most needs.
  • Its granularity is consistent. A universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised sensibly, because the units are not comparable.

Each auditable unit carries risk attributes, an owner, and — crucially — when it was last audited and what was found.

Coverage is the question the universe exists to answer: what proportion of the universe, weighted by risk, has been audited within the cycle? An area never audited in five years is a finding about the plan, not about the area.

The annual plan is built from the universe, prioritised by risk. A defensible plan usually weighs:

  • Inherent risk of the auditable unit — materiality, complexity, change, regulatory exposure, fraud susceptibility.
  • Control maturity, where known — often informed by the organisation’s ICoFR work in a system like Nextera Guard.
  • Time since last audit, and what that audit found.
  • Management and audit committee requests, held in tension with independence: internal audit takes input on the plan, but the plan is not set by the auditee.
  • Available resource — the plan is constrained by auditor days, and pretending otherwise produces a plan that fails in Q3.

Assurance mapping is the discipline of recording who else already provides assurance over each area — external audit, regulators, second-line functions, certification bodies — so internal audit can direct effort where it is the only assurance, rather than duplicating.

Plans change. What matters is that changes are visible and approved, not that the plan was perfect in January.

An engagement runs through a recognisable sequence:

  1. Scope and terms of reference. Objectives, boundaries, period, criteria, and the engagement’s own risk assessment. Agreed with the auditee, approved within audit.
  2. Planning. The audit programme — what will be tested, how, and by whom.
  3. Fieldwork. Performing the tests and gathering evidence.
  4. Working papers. The record of what was done.
  5. Findings. Raised, discussed, and agreed with management.
  6. Report. Issued to management and, in summary, to the audit committee.
  7. Follow-up. Verification that agreed actions were completed.

Working papers carry a specific professional standard: a competent reviewer with no prior connection to the engagement should be able to read them and understand what was tested, what was found, and why the conclusion follows. That standard — not tidiness — is what makes working paper structure worth enforcing.

Review is the corresponding control: work is reviewed by someone more senior before conclusions are issued, and the review itself is evidenced.

Every well-formed finding has all five. Missing elements are the most common reason a finding is disputed or ignored:

Element The question it answers
Criteria What should be happening — policy, standard, regulation, control design
Condition What is happening
Cause Why the gap exists
Effect What the gap could lead to — quantified wherever possible
Recommendation What should change

Cause is the element most often skipped, and it is the one that determines whether remediation works. A finding that says “reconciliations were not performed” without establishing why — no owner, no time, no system access, no understanding of the requirement — produces a management action that fixes the symptom and recurs next year.

Effect is what converts a finding from an observation into a priority. “Three of twenty reconciliations were late” is an observation; “three of twenty reconciliations were late, covering IDR 40 billion of balances, and one contained an uncorrected error” is a finding.

Ratings exist so that limited management attention goes to the right places. Any scale works as long as it is defined, applied consistently, and calibrated against impact and likelihood rather than against how annoyed the auditor was.

Two rating levels are usually needed and often confused:

  • Finding rating — the severity of the individual issue.
  • Engagement opinion — the overall conclusion on the area audited. An area can receive several low findings and still warrant an adverse overall opinion if together they show the control environment is weak.

Definitions should be published in the methodology and applied by the same people who wrote them. An unwritten scale becomes a negotiation.

Each finding gets a management response containing three things and no fewer: an agreed action, a named owner, and a due date. “Noted” is not a response.

Where management accepts the risk rather than acting, that is a legitimate outcome — but it must be explicitly recorded as risk acceptance at an appropriate level of authority, not allowed to become a permanently overdue action.

Follow-up is where most audit functions lose value, and the reason is structural rather than cultural. Findings are raised in engagement-shaped batches, but they come due continuously and long after the engagement closed. If actions live in the engagement’s own file, nobody can answer the audit committee’s actual question — how many high-rated actions are overdue across everything? — without reassembling it by hand.

Verification closes the loop: internal audit confirms the action was completed and, more importantly, that it addressed the cause. Closing on management’s assertion alone undermines the whole cycle.

Audit committee reporting is a different product from an engagement report, drawn from the same data: plan progress against the approved plan, coverage of the universe, findings by rating and by theme, overdue actions with ageing, and matters the committee needs to decide.

The value of generating it from the same underlying records is that the numbers cannot drift between the engagement file and the committee pack — which is the failure mode of every spreadsheet-based audit function.

Concept on this page Nextera Trace module
The maintained population of auditable entities and processes Audit universe
Risk-based prioritisation into an approved annual plan Audit planning
Scope, fieldwork and working papers for each engagement Audit execution
The five elements, rating, and agreement with management Findings & recommendations
Agreed actions tracked to closure with live status Follow-up tracking
Engagement and committee reporting from the same data Audit reporting